[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21448-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":40,"duplicates":41,"related":42,"reserved_at":9,"published_at":56,"modified_at":57,"state":9,"summary":58,"references_raw":60,"kevs":172,"epss":9,"epss_history":173,"metrics":174,"affected":175},"OPENSUSE-SU-2026:21448-1","Security update for agama-web-ui\n\nThis update for agama-web-ui fixes the following issues:\n\n- CVE-2025-7783: form-data: unsafe `Math.random()` function is used to select a boundary value for multipart\n  form-encoded data (bsc#1246822).\n- CVE-2026-12143: form-data: CRLF injection via unescaped multipart field names and filenames (bsc#1272310).\n- CVE-2026-13149: brace-expansion: `expand()` function exhibits exponential-time complexity when processing\n  non-expanding `{}` brace groups (bsc#1269927).\n- CVE-2026-13311: shell-quote: quadratic complexity in `parse()` function when processing specially crafted strings\n  (bsc#1269359).\n- CVE-2026-13676: fast-uri: host-based policy bypass due to failure to canonicalize Unicode/IDN hostnames for\n  HTTP-family URLs (bsc#1269595).\n- CVE-2026-27601: underscore: DoS via stack overflow due to missing depth limits in `_.flatten` and `_.isEqual`\n  functions (bsc#1259169).\n- CVE-2026-40181: react-router: open redirect to an external domain due to path values starting with `//` being\n  reinterpreted as protocol-relative URLs (bsc#1272311).\n- CVE-2026-49356: @babel/core: arbitrary file read via `sourceMappingURL` comment (bsc#1272317).\n- CVE-2026-53550: js-yaml: quadratic complexity in merge-key processing when processing a crafted YAML document\n  (bsc#1268851).\n- CVE-2026-53632: launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows (bsc#1272319).\n- CVE-2026-54466: websocket-driver: message corruption via abuse of protocol length headers (bsc#1272312).\n- CVE-2026-54490: websocket-driver: resource limit bypass via message compression (bsc#1272313).\n- CVE-2026-55602: http-proxy-middleware: Host-header-driven backend routing bypass via `router` host+path substring\n  matching (bsc#1272318).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38],{"_key":15},"CVE-2025-7783",{"_key":17},"CVE-2026-12143",{"_key":19},"CVE-2026-13149",{"_key":21},"CVE-2026-13311",{"_key":23},"CVE-2026-13676",{"_key":25},"CVE-2026-27601",{"_key":27},"CVE-2026-40181",{"_key":29},"CVE-2026-49356",{"_key":31},"CVE-2026-53550",{"_key":33},"CVE-2026-53632",{"_key":35},"CVE-2026-54466",{"_key":37},"CVE-2026-54490",{"_key":39},"CVE-2026-55602",[],[],[43,44,45,46,47,48,49,50,51,52,53,54,55],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},"2026-07-27T15:55:38Z","2026-07-29T18:24:28.648555524Z",{"cisa_kev":59,"cisa_ransomware":59,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[61,67,71,75,79,83,87,91,95,99,103,107,111,115,119,124,128,132,136,140,144,148,152,156,160,164,168],{"url":62,"sources":63,"tags":65},"https://bugzilla.suse.com/1246822",[64],"osv_opensuse",[66],"REPORT",{"url":68,"sources":69,"tags":70},"https://bugzilla.suse.com/1259169",[64],[66],{"url":72,"sources":73,"tags":74},"https://bugzilla.suse.com/1268851",[64],[66],{"url":76,"sources":77,"tags":78},"https://bugzilla.suse.com/1269359",[64],[66],{"url":80,"sources":81,"tags":82},"https://bugzilla.suse.com/1269514",[64],[66],{"url":84,"sources":85,"tags":86},"https://bugzilla.suse.com/1269595",[64],[66],{"url":88,"sources":89,"tags":90},"https://bugzilla.suse.com/1269927",[64],[66],{"url":92,"sources":93,"tags":94},"https://bugzilla.suse.com/1272310",[64],[66],{"url":96,"sources":97,"tags":98},"https://bugzilla.suse.com/1272311",[64],[66],{"url":100,"sources":101,"tags":102},"https://bugzilla.suse.com/1272312",[64],[66],{"url":104,"sources":105,"tags":106},"https://bugzilla.suse.com/1272313",[64],[66],{"url":108,"sources":109,"tags":110},"https://bugzilla.suse.com/1272317",[64],[66],{"url":112,"sources":113,"tags":114},"https://bugzilla.suse.com/1272318",[64],[66],{"url":116,"sources":117,"tags":118},"https://bugzilla.suse.com/1272319",[64],[66],{"url":120,"sources":121,"tags":122},"https://www.suse.com/security/cve/CVE-2025-7783",[64],[123],"WEB",{"url":125,"sources":126,"tags":127},"https://www.suse.com/security/cve/CVE-2026-12143",[64],[123],{"url":129,"sources":130,"tags":131},"https://www.suse.com/security/cve/CVE-2026-13149",[64],[123],{"url":133,"sources":134,"tags":135},"https://www.suse.com/security/cve/CVE-2026-13311",[64],[123],{"url":137,"sources":138,"tags":139},"https://www.suse.com/security/cve/CVE-2026-13676",[64],[123],{"url":141,"sources":142,"tags":143},"https://www.suse.com/security/cve/CVE-2026-27601",[64],[123],{"url":145,"sources":146,"tags":147},"https://www.suse.com/security/cve/CVE-2026-40181",[64],[123],{"url":149,"sources":150,"tags":151},"https://www.suse.com/security/cve/CVE-2026-49356",[64],[123],{"url":153,"sources":154,"tags":155},"https://www.suse.com/security/cve/CVE-2026-53550",[64],[123],{"url":157,"sources":158,"tags":159},"https://www.suse.com/security/cve/CVE-2026-53632",[64],[123],{"url":161,"sources":162,"tags":163},"https://www.suse.com/security/cve/CVE-2026-54466",[64],[123],{"url":165,"sources":166,"tags":167},"https://www.suse.com/security/cve/CVE-2026-54490",[64],[123],{"url":169,"sources":170,"tags":171},"https://www.suse.com/security/cve/CVE-2026-55602",[64],[123],[],[],[],[176],{"ecosystem":177,"name":178,"vendor":179,"product":180,"cpe_part":9,"purl_type":181,"purl_namespace":179,"purl_name":180,"source":9,"versions":182},"openSUSE","agama-web-ui","opensuse","agama-web-ui&distro=openSUSE Leap 16.0","rpm",[183],{"version":184,"is_range":185,"range_type":186,"version_start":9,"version_start_type":9,"version_end":187,"version_end_type":188,"fixed_in":9},"lt17+673_b97ba64d6_160000_12_1",true,"ecosystem","17+673.b97ba64d6-160000.12.1","excluding"]